OS Command injection in Apache Airflow
High severity
GitHub Reviewed
Published
Feb 26, 2022
to the GitHub Advisory Database
•
Updated Sep 12, 2024
Description
Published by the National Vulnerability Database
Feb 25, 2022
Published to the GitHub Advisory Database
Feb 26, 2022
Reviewed
Mar 1, 2022
Last updated
Sep 12, 2024
In Apache Airflow, prior to version 2.2.4, some example DAGs did not properly sanitize user-provided params, making them susceptible to OS Command Injection from the web UI.
References